SCADA security using SSH honeypot

被引:8
作者
Belqruch, Amine [1 ]
Maach, Abdelilah [1 ]
机构
[1] Mohamed V Univ Agdal, LRIE, Mohammadia Sch Engineers, Rabat, Morocco
来源
PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON NETWORKING, INFORMATION SYSTEMS & SECURITY (NISS19) | 2019年
关键词
Smart Grid; SCADA; ICS; Security; Honeypot; Kippo; kippo-graph;
D O I
10.1145/3320326.3320328
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Industrial Control System (ICS) is a term that refers to control systems in production, transmission and distribution architecture in Smart Grid. These systems can be SCADA (Supervisory Control and Data Acquisition System) and DCS (Distributed Control Systems). ICS have moved from proprietary system to open and standard technologies interconnected with others networks such as Internet. This move to interconnecting ICS with others networks have exposed this system to different attacks and have revealed serious weaknesses. So, these systems must deployed protection measures like IDS, Firewalls, IPS and others. However, detection based on these measures is often based on prior knowledge of the attacks themselves and are not able to study the behavior and techniques used by attackers, which means that new attacks are not detectable by them. So, in order to detect new attacks, understand malicious activities targeting ICS, and analyses attackers' behaviors and techniques used by them, in this article, we use a SSH honeypot tool called Kippo in order to log brute force attacks and shell interaction performed by attackers in order to take attention away in the production server.
引用
收藏
页数:5
相关论文
共 15 条
[1]  
AlShaer E, 2016, ADV INFORM SECUR, V67, P1, DOI 10.1007/978-3-319-32871-3
[2]  
[Anonymous], 2015, SMART GRID SECURITY
[3]  
[Anonymous], 2006, Securing SCADA Systems
[4]  
Cuellar Jorge, 2012, NIST2 SMART GRID SEC
[5]  
Gilbert N, 2016, SMART GRID SECURITY
[6]  
Jicha Arthur F, 2016, SCADA HONEYPOTS IN D
[7]  
Knapp ED, 2013, APPLIED CYBER SECURITY AND THE SMART GRID: IMPLEMENTING SECURITY CONTROLS INTO THE MODERN POWER INFRASTRUCTURE, P1
[8]  
Pothamsetty V., 2005, Scada honeynet project: Building honeypots for industrial networks
[9]   A SYMBOLIC HONEYNET FRAMEWORK FOR SCADA SYSTEM THREAT INTELLIGENCE [J].
Redwood, Owen ;
Lawrence, Joshua ;
Burmester, Mike .
CRITICAL INFRASTRUCTURE PROTECTION IX, 2015, 466 :103-118
[10]  
Scott Charlie., 2014, Designing and Implementing a Honeypot for a SCADA Network